Title : BEA Weblogic Apache Connector Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-2145 CVE ID : CVE-2008-3257 CWE ID : CWE-119
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-22
Technical Description
A vulnerability has been identified in BEA Weblogic Server, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error in the Apache connector when processing overly long POST requests, which could be exploited by attackers to crash an affected server or execute arbitrary code via a specially crafted HTTP request.